started · updated
Critical Flaws Found in BlackBerry UEM, WordPress Plugin, and ManageEngine
A cross‑site scripting (XSS) vulnerability (CVE‑2026‑18084) was disclosed in BlackBerry UEM Management Console versions prior to QF9. An unauthenticated attacker can inject malicious JavaScript that, when viewed by an administrator, steals session tokens and can take over the console. The Uganda National CERT urges immediate deployment of the QF9 patch, IP‑based access restrictions and multi‑factor authentication.
A supply‑chain backdoor (CVE‑2026‑18072) was found in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7. The malicious code allows any remote attacker to bypass authentication, impersonate an administrator and relay the compromised site URL and admin username to a fonts.wp.com command‑and‑control server. Wordfence reported the issue within two hours of detection and the plugin was removed from the WordPress.org repository.
ManageEngine ADAudit Plus (CVE‑2026‑6516) contains an authentication‑bypass and path‑traversal flaw that enables remote code execution on builds earlier than 8606. The vulnerability scores a CVSS v3.1 of 10.0. ManageEngine advises upgrading to build 8606 and updating associated Windows and macOS agents.
Entities
Advanced Responsive Video Embedder · Advanced Responsive Video Embedder WordPress plugin · BlackBerry Ltd · BlackBerry UEM Management Console · Fontswp.com · ManageEngine (Zoho Corporation) · ManageEngine ADAudit Plus · Uganda National Computer Emergency Response Team · WordPress.org · Wordfence
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] CVE‑2026‑18084 is a cross‑site scripting vulnerability in BlackBerry UEM Management Console versions prior to QF9. cert.ug
- [○ 1 SOURCE] CVE‑2026‑6516 is a pre‑authentication remote‑code‑execution vulnerability in ManageEngine ADAudit Plus builds prior to 8606, with CVSS 10.0. horizon3.ai
- [○ 1 SOURCE] CVE‑2026‑18072 is a supply‑chain backdoor in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7, rated CVSS 9.8. cybersecuritynews.com
- [○ 1 SOURCE] Exploitation of CVE‑2026‑6516 may allow an unauthenticated attacker to write files outside intended directories and execute code; no confirmed active exploitation has been reported. horizon3.ai
- [○ 1 SOURCE] The backdoor allows an unauthenticated attacker to impersonate a WordPress administrator and send site URL and admin username to an attacker‑controlled server. cybersecuritynews.com
- [○ 1 SOURCE] Exploitation of CVE‑2026‑18084 can allow an unauthenticated attacker to execute JavaScript in an admin’s browser and potentially steal session tokens and take over the console. cert.ug
- [○ 1 SOURCE] CVE-2026-18084 is a cross‑site scripting vulnerability in BlackBerry UEM Management Console before version QF9 that allows unauthenticated remote attackers to inject malicious JavaScript and take over cert.ug
- [○ 1 SOURCE] The Uganda National CERT recommends applying the QF9 patch, enabling MFA, restricting console IP access, and monitoring logs to mitigate CVE-2026-18084 cert.ug
- [○ 1 SOURCE] CVE-2026-6516 is a pre‑authentication remote‑code‑execution vulnerability in ManageEngine ADAudit Plus Agent APIs affecting builds before 8606 with CVSS 10.0 horizon3.ai
- [○ 1 SOURCE] The backdoor sends the compromised site’s URL and selected administrator username to the C2 server fontswp.com cybersecuritynews.com
- [○ 1 SOURCE] CVE-2026-18072 is a supply‑chain backdoor in the Advanced Responsive Video Embedder WordPress plugin version 10.8.7 that gives unauthenticated attackers full administrator access cybersecuritynews.com
- [○ 1 SOURCE] ManageEngine released patch build 8606 to fix CVE-2026-6516 and advises users to upgrade horizon3.ai